{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-83540", "assignerOrgId": "50d2cd11-d01a-48ed-9441-5bfce9d63b27", "state": "PUBLISHED", "assignerShortName": "wolfSSL", "dateReserved": "2026-08-31T17:29:54.256Z", "datePublished": "2026-10-07T02:40:35.137Z", "dateUpdated": "2026-10-07T02:40:35.137Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "50d2cd11-d01a-48ed-9441-5bfce9d63b27", "shortName": "wolfSSL", "dateUpdated": "2026-10-07T02:40:35.137Z" }, "title": "wolfSSHd on Windows race condition leading to logon token reused across connections", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-287", "description": "CWE-287 Improper Authentication", "type": "CWE" }, { "lang": "en", "cweId": "CWE-613", "description": "CWE-613 Insufficient Session Expiration", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-233", "descriptions": [ { "lang": "en", "value": "CAPEC-233 Privilege Escalation" } ] } ], "affected": [ { "vendor": "wolfSSL", "product": "wolfSSH", "platforms": [ "Windows" ], "collectionURL": "https://github.com/wolfSSL/wolfssh", "repo": "https://github.com/wolfSSL/wolfssh", "modules": [ "wolfSSHd" ], "programFiles": [ "apps/wolfsshd/auth.c" ], "programRoutines": [ { "name": "SetupUserTokenWin" }, { "name": "CheckPasswordWIN" } ], "versions": [ { "status": "affected", "version": "1.4.15", "lessThanOrEqual": "1.5.0", "changes": [ { "at": "1.6.0", "status": "unaffected" } ], "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.
" } ] } ], "references": [ { "url": "https://github.com/wolfSSL/wolfssh", "name": "wolfSSH source repository", "tags": [ "product" ] }, { "url": "https://github.com/wolfSSL/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9", "name": "Fix: give each Windows wolfSSHd connection its own authentication context", "tags": [ "patch" ] }, { "url": "https://github.com/wolfSSL/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a", "name": "Fix: add Windows sanity close of token before acquiring a new one", "tags": [ "patch" ] }, { "url": "https://www.wolfssl.com/docs/security-vulnerabilities/", "name": "wolfSSL security vulnerabilities page", "tags": [ "vendor-advisory" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "PRESENT", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "HIGH", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "HIGH", "baseScore": 7.7, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } } ], "configurations": [ { "lang": "en", "value": "wolfSSHd built for and running on Windows with password or public key authentication enabled.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "wolfSSHd built for and running on Windows with password or public key authentication enabled.
" } ] } ], "workarounds": [ { "lang": "en", "value": "Restrict which accounts may connect to the affected wolfSSHd instance on Windows hosts until the server is upgraded. Disabling public key authentication alone does not help, because password authentication is affected as well.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Restrict which accounts may connect to the affected wolfSSHd instance on Windows hosts until the server is upgraded. Disabling public key authentication alone does not help, because password authentication is affected as well.
" } ] } ], "credits": [ { "lang": "en", "value": "Found by internal wolfSSL testing", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 0.2.0" } } } }